VYPR

Leantime

by Leantime

Source repositories

CVEs (22)

  • CVE-2026-15509MedJul 12, 2026
    risk 0.00cvss 6.3epss 0.00

    A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint. The manipulation of the argument role leads to improper authorization. The attack is possible to be carried out remotely. The exploit has been…

  • CVE-2023-45826MedOct 19, 2023
    risk 0.00cvss 6.5epss 0.02

    Leantime is an open source project management system. A 'userId' variable in `app/domain/files/repositories/class.files.php` is not parameterized. An authenticated attacker can send a carefully crafted POST request to `/api/jsonrpc` to exploit an SQL injection vulnerability.…

Page 2 of 2